{"id":"CVE-2024-11584","details":"cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the \"/run/cloud-init/hook-hotplug-cmd\" FIFO. An unprivileged user could trigger hotplug-hook commands.","modified":"2026-08-12T03:51:26.252668701Z","published":"2025-06-26T09:25:20.199Z","related":["SUSE-RU-2026:20174-1","SUSE-RU-2026:20192-1","SUSE-SU-2025:20656-1","SUSE-SU-2025:20755-1","SUSE-SU-2026:1980-1","openSUSE-RU-2026:20129-1","openSUSE-SU-2025:15376-1"],"database_specific":{"cna_assigner":"canonical","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11584.json"},"references":[{"type":"WEB","url":"https://github.com/canonical/cloud-init/pull/6265/commits/6e10240a7f0a2d6110b398640b3fd46cfa9a7cf3"},{"type":"WEB","url":"https://github.com/canonical/cloud-init/releases/tag/25.1.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11584.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-11584"},{"type":"PACKAGE","url":"https://github.com/canonical/cloud-init"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canonical/cloud-init","events":[{"introduced":"03ee10cd378773fab50eacf6fce3c55e8f828879"},{"fixed":"79ac5c8311efb8b89bca129cc8a0098ca5ef679d"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:canonical:cloud-init:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"21.3"},{"fixed":"25.1.3"},{"introduced":"0"}]}}],"versions":["25.1.2","25.1.1","25.1","24.4","24.3","24.2","23.4","23.3","23.2","23.1","22.4","22.3","22.2","22.1","21.4","21.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11584.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}